
Cloud Vulnerability DB
A community-led vulnerabilities database
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit WordPress plugin version 2.3.6 and earlier contains a vulnerability related to arbitrary file upload (Wordfence Intel). The vulnerability was discovered by researcher Lucio Sá and was assigned CVE-2024-13882 with a disclosure date of March 7, 2025.
The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (High) with the following vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. This indicates that the vulnerability can be exploited remotely with low attack complexity, requires low privileges, and no user interaction (Wordfence Intel).
If successfully exploited, this vulnerability could allow an attacker to upload arbitrary files to the affected WordPress installation, potentially leading to high impacts on confidentiality, integrity, and availability of the system (Wordfence Intel).
Website administrators running the affected plugin versions should update to a patched version when available. In the meantime, considering the severity of the vulnerability, administrators should consider disabling the plugin until a fix is released (Wordfence Intel).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."